Severity scale:  

Remove Google redirect (Virus Removal Guide) - updated Dec 2020

removal by Jake Doevan - -   Also known as Google hijacker | Type: Browser Hijackers

Google redirect virus is a set of potentially dangerous computer infections that seek to benefit from ad revenue while exposing users to unsafe content

Google Redirect virus (search results)

Google redirect virus” is a term used to describe browser hijackers,[1] adware and other potentially unwanted programs that display intrusive advertisements, change the homepage, alter search results on Chrome web browser. As evident, these infections have nothing to do with Google and are created by third-parties that seek to monetize on ad revenue. In the meantime, users' web browsing experience suffers, as they struggle to find relevant information, battle the annoying pop-ups and have to deal with the slow operation of the browser.

Questions about Google redirect

On the other hand, Google itself has received enough criticism for spying on its users[2], bypassing phishing links[3] among its search results and allowing malicious apps into Chrome Web Store or Google Play Store.[4] Despite that, the industry giant is trying to reduce the malware inside its own store by tightening its security, improving scanners that block malicious URLs and providing users with plenty of information on how site admins can protect their visitors from malware.[5]

Name Google redirect
Type Adware, browser hijackers and other PUPs that affect Google Chrome web browser
Infection means Third-party websites, bundled software, advertisements, official sites of unwanted programs
Symptoms Symptoms vary depending on type of infection; however, users will notice strange behavior on Google Chrome, such as frequent redirects to suspicious sites, pop-up ads, alternative search results, changed startup page and new tab URL, etc.
Risk factors Malware infection, money loss, sensitive information disclosure to unknown parties, etc.
Detection and termination You can always check the list of the installed app on your device and terminate them manually (check our guide below); alternatively, you can use security software that focuses on potentially unwanted apps, such as SpyHunter 5Combo Cleaner
Recovery Some PUPs might act as malware and alter system settings or infect core files. To revert the damage done, use ReimageIntego

The majority of complaints, reporting URL redirects on Google page, and similar search engines, was recorded in 2012.[6] However, the threat is still viable as it surfaces once in a while. Both Windows 10, Linux, and Mac OS users can be victimized. Note that Google redirect virus iPhone and Android versions also exist. Alternatively, this virus is known as Chrome redirect virus

There is no wonder why the Google redirect virus is so active this year. Browser hijackers causing redirects typically target Google Chrome users because it is the most popular web browser in the world. Clearly, it means that attacking users of this browser means hitting the right spot with the biggest number of potential victims.

Some experts tend to shorten the term and simply call the infection as Google virus. However, we want to clarify the meaning of it. Google virus is a potentially unwanted program (usually a browser hijacker) that meddles with browser settings and worsens user's browsing and search experience. Typically, such programs are designed to collect victim's search terms and browsing history data and contaminate regular search results with ads.

In case you noticed an excessive amount of ads in your Google search results or if the appearance of them raises your suspicion, check your system for a browser redirect virus. Some of the programs known to be causing such redirects are: 

Google Redirect browser hijackersA variety of browser hijackers might affect Google Chrome browser

In case you have been noticed that Google redirects you to Yahoo[7] or other domains (these sites can be either well-known ones or totally new to you), you should take necessary measures to solve the problem. Just like Yahoo Redirect virus and Bing redirect virus, Safari redirect virus, it functions as a hybrid of a browser hijacker and a potentially unwanted program.[8]

The main problem here is its elimination – the infection can hide under any URL domain name, so it might troublesome to eradicate it manually. ReimageIntego  or Malwarebytes speed up Google redirect virus removal process. They also save your time by wiping all web scripts and “helper elements.” It is of utmost importance to “uninstall” them all in order not to experience this issue again.

Some users start wondering if they're infected with some Google virus after experiencing “Google bookmarks redirecting” issue. If your browser unexpectedly initiates a redirect loop once you attempt to open your bookmarks, do not worry. This issue is common and can be fixed quite easily. Usually, all that it takes to fix the problem is to clear browser cache, cookies, and history, or to sign out of your Google account, close the browser and sign in again.

Do not trust Google Lead Services – its is not related to the real technology company

Google Lead Services is a threat to your computer, and it is not related to Google Ad Services (all the concepts, features, and networks that comprise Google AdWords account). You should know that redirects through occur each time you click on an ad in legitimate Google search results, however, if you happen to be using a fake version of it or a search engine controlled by a browser hijacker, you might experience redirects that go through If you check the website, it states the following (this hoax has nothing to do with Google):

We are not affiliated with or related to Google Lead Services™ in any way. The term “Google” is used as a synonym for “Search”

Google Redirect Google Lead ServicesGoogle Lead Services has nothing to do with the industry giant Google

It seems that the problem with this domain has been bothering both Windows and Mac users for years. Some people complain about Google Lead Services Cookie that prevents smooth navigation in Safari and other browsers. If you have run into this domain during your browsing session, we highly suggest scanning your computer and removing all files and components associated with it.

In case you experience continuous redirects to the described domain, check if your browser's shortcuts aren't affected. You can find a comprehensive tutorial on how to do it right below the article.

Dangers of Google Redirect virus

“Is Google redirect virus dangerous”? This is one of the questions curious users might ask. Though technically, it is not as complex as Petna or Cerber malware, its consequences might be as annoying as those caused by these ransomware-type threats.

Before we discuss the prevention of browser hijackers, let's take a look at the most common symptoms of this infection:

  • Google redirects to Comcast, Bing, Yahoo and similar websites. Naturally, it might trigger the appearance of pop-up alerts. In any case, such behavior indicates that the browser is plagued by a browser infection.
  • Altered browser and system settings. Typically, this virus changes the default search engine, new tab, and the homepage. It might also append extra extensions.
  • Foisted commercial content in the search results. If Google search engine is changed to some fishy Ask or PlusNetwork tool, you might notice more commercial ads beside the search result.
  • Tracking your online activities. More aggressive versions of browser redirect viruses might not only compile information about your frequently visited websites and search entries, but gather personal details, such as name, email, IP and home addresses, and trade this data with business partners. 

Such phenomena should not be ignored even if excessive advertising does not bother you. This issue has nothing to do with safe browsing and, even if you have a reputable malware elimination tool installed on your computer, remain vigilant while adding a new toolbar or a browser extension.

Google Redirect virusGoogle redirect is a browser infection that has many forms of disguise. The easiest way to remove Google redirect virus is to scan the system with updated security software.

Google redirect scheme becomes more and more popular

Redirecting users to modified versions of Google, injecting ads and collecting victims' search terms helps companies make money by driving traffic to predetermined sites. Some of the authors of such redirect viruses join hands with online advertisers or specific third parties. By directing users to certain websites, they get a certain share of the profit from web traffic.

As we have already mentioned, some of these sites can be entirely harmless (Yahoo, Bing, Facebook or Comcast), but it does not apply to all of them. Modified search results can contain links pointing straight to deceptive or malicious Internet sites you definitely do not want to enter.

If you notice something suspicious, or if you feel that you can't trust Google results, check if your system isn't infected with:

  • browser hijacker
  • adware app
  • other potentially unwanted program
  • malware

Be aware that the matter is extremely dangerous and can compromise your computer by stopping it from functioning normally, locking your files, stealing your credentials or other sensitive data, or even corrupting Windows operating system.

Do not trust apps only because they are on Chrome Web Store

Chrome Web Store as such has been launched in 2010. Since then, millions of Chrome extensions have been downloaded by Chrome users and, luckily, most of them were lucky to download original variants. Unfortunately, in 2015 complaints started spreading about copycat extensions being spread on the Store infecting users with adware and browser hijacking malware that initiates active Google redirect campaigns. 

One of the first cases spotted in 2015[9] on the Chrome Web Store was related to the fake AdBlock Super, AdBlock Plus, and other AdBlock applications. Millions of people installed highly popular AdBlock apps believing that they are genuine. However, these rogue variants not only failed to block intrusive advertising but also led to Google redirect virus promoting prodownnet extension download site. 

In other words, the Chrome Web Store has become a spamming platform due to a lack of control over apps that are being offered. According to researchers, the fake AdBlock apps have been downloaded by millions of people who later on started suffering prodownnet redirects to the following domains:


Although the prodownnet virus is not the most suitable term to describe a website that promotes malware, many people on forums[10] expressed their anger about intrusive browser hijacking and unstoppable Google redirects to the mentioned domains. The fact that the mentioned redirect virus is actively promoting other malware is worse than the redirects in general. 

Once the fake Adblock app is installed, browser's settings are altered in a way to redirects people to and, or another malicious website, where they are asked to download more malicious apps. These are the apps being promoted:

  • Adguard
  • GOM Media Player
  • Facebook Video Downloader
  • VLC Media Player
  • Retrica
  • Internet Download Manager
  • Adblock Plus Chrome
  • Adblock Super
  • Adblock Pro
  • Adblock Plus Popup
  • AdBlock
  • AdBlock Plus
  • Zenmate
  • Periscope
  • Scorp
  • Shazam, etc.

Google redirect virus after Adblock installPeople report about intrusive Google redirect symptoms after installing prodownnet Adblock on Chrome Web Store

Moreover, such Google redirects can also lead to a browser hijacking. Upon installation of fake Adblock apps and redirect to prodownnet, Chrome's start page, search provider, new tab URL, and other settings can be aggressively modified. Despite being annoying, such changes pose the risk of redirects to unwanted or potentially dangerous domains, which is why we strongly recommend being very careful with malware and eliminate it asap. 

It seems that the domain has been suspended, as well as the apps that promoted it have been taken from the Chrome Web Store. Nevertheless, people keep looking for answers on how do I get rid of a browser hijacker that redirects to or related sites, so be careful and do not slip on ad-supported rogue adblockers that can diminish your web browsing experience. 

Keep in mind that despite multiple measures that Google's team takes to protect the Chrome Web Store from malware, hackers seem to be a step forward. In spring 2020, researchers reported 500 Chrome extensions[11] found on the store that have been freely harvesting browsing data and transmitting it to C2 servers. Besides, they've also been included in the Google redirect scheme and promoting malware like prodownnet virus. 

Therefore, it's important to investigate each extension before downloading it from seemingly trustworthy sources. Read the comments section and check the web for the findings of cybersecurity experts. If you see flags about the extension being ma;ware-related, do not install it under any circumstances.

People who noticed suspicious Google redirect symptoms wight after visiting the Chrome Web Store should try to remove prodownnet and related PUPs from the system. The best way to do that is to run an automated scan with SpyHunter 5Combo Cleaner or a similar utility.

Avoid malware using these easy tips

At first glance, it may seem that installing a free application from trusted sources will exclude you from the burden of PUP  and malware. However, few users realize that even recklessly installing the latest update of Skype or Java might lead them to install unwanted elements, such as adware, browser hijackers [12], as well.

What you have to do when installing freeware and shareware is to monitor its installation process carefully. Choose “Custom” or “Advanced” installation method. It discloses optional download options. Remove the checkmarks from irrelevant add-ons and only then click on the “Install” button.

Quite often, users might be mislead by skipping text in fine print during the installation procedure. It usually states the following:

By clicking Next, you agree to the Terms and conditions and Privacy Policy and consent to install [app name] app. Your browser may be restarted

For that reason, it is extremely important to check all the fine print, otherwise you might agree to things you never would,

Google Redirect installationUsers often install Google Redirect virus when not looking at the installation procedure of shareware carefully

Due to the flexible form, the malware might also function via web scripts. In that case, you might not spot any specific changes in the browser. Luckily, even then, there is a solution. Proceed to Google redirect removal section.

Remove Google redirect virus from your PC

Run an anti-spyware tool to start Google redirect virus removal process. The software will also locate delete the registry keys associated with this threat. After scanning the system, you need to look over detected items and remove them all at once. With a help of anti-spyware program, this can be done in a single mouse click. They instruct how to get rid of unwanted and dubious browser add-ons.

Full browser reset also facilitates the removal process. If you are still bothered by the occasional redirects, change your proxy settings and host file. You can find the instructions specific for your browser on the Web. Now proceed to the below guidelines. Safari users will also find the Google redirect scam removal instructions for their browser.

Though the infection is widely spread and operates already for several users, it might take the liking of users residing in a specific country, for instance, Germany.[13]

You may remove virus damage with a help of ReimageIntego. SpyHunter 5Combo Cleaner and Malwarebytes are recommended to detect potentially unwanted programs and viruses with all their files and registry entries that are related to them.

do it now!
Reimage Happiness
Intego Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Intego, submit a question to our support team and provide as much details as possible.
Reimage Intego has a free limited scanner. Reimage Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

To remove Google redirect, follow these steps:

Remove Google from Windows systems

To get rid of Google redirect problem, you need to uninstall all programs/apps that seem suspicious. Also, you should definitely get rid of programs that you can't remember installing on your computer.

  1. Click Start Control Panel Programs and Features (if you are Windows XP user, click on Add/Remove Programs). Click 'Start -> Control Panel -> Programs and Features' (if you are 'Windows XP' user, click on 'Add/Remove Programs').
  2. If you are Windows 10 / Windows 8 user, then right-click in the lower left corner of the screen. Once Quick Access Menu shows up, select Control Panel and Uninstall a Program. If you are 'Windows 10 / Windows 8' user, then right-click in the lower left corner of the screen. Once 'Quick Access Menu' shows up, select 'Control Panel' and 'Uninstall a Program'.
  3. Uninstall Google and related programs
    Here, look for Google or any other recently installed suspicious programs.
  4. Uninstall them and click OK to save these changes. Right click on each of suspicious entries and select 'Uninstall'
  5. Remove Google from Windows shortcuts
    Right click on the shortcut of Mozilla Firefox and select Properties. Right click on browsers' icon and select 'Properties'
  6. Go to Shortcut tab and look at the Target field. Delete malicious URL that is related to your virus. Select 'Shortcut' tab and delete '' or other suspicious URL

Repeat steps that are given above with all browsers' shortcuts, including Internet Explorer and Google Chrome. Make sure you check all locations of these shortcuts, including Desktop, Start Menu and taskbar.

Delete Google from Mac OS X system

To fix your Mac OS X, you should try to find all entries that seem unknown to you. All apps that you can't remember installing on your computer should be eliminated.

If your macOS is displaying some infection symptoms, proceed with the following guide:

Remove Google redirect from Applications folder:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for Google redirect-related entries.
  3. Click on the app and drag it to Trash (or right-click and pick Move to Trash)Uninstall from Mac 1

To fully remove Google redirect, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and click Go or press Enter.
  3. In the Application Support folder, look for any dubious entries related to Google redirect and then delete them.
  4. Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the Google redirect-related entries.Uninstall from Mac 2

Uninstall Google from Internet Explorer (IE)

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for Google redirect and other suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example,
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete…
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset again to complete Google redirect removal.Reset Internet Explorer

Eliminate Google redirect from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the Google redirect-related extension and click on the Gear icon.
  3. Click on Uninstall at the bottom.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Privacy & security.
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select everything (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Reset MS Edge if that above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge

If this solution failed to help you, you need to use an advanced Edge reset method. Note that you need to backup your data before proceeding.

  1. Find the following folder on your computer: C:\\Users\\%username%\\AppData\\Local\\Packages\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe.
  2. Press Ctrl + A on your keyboard to select all folders.
  3. Right-click on them and pick DeleteAdvanced MS Edge reset 1
  4. Now right-click on the Start button and pick Windows PowerShell (Admin).
  5. When the new window opens, copy and paste the following command, and then press Enter:

    Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register “$($_.InstallLocation)\\AppXManifest.xml” -VerboseAdvanced MS Edge reset 2

Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.Reset Chromium Edge

Erase Google from Mozilla Firefox (FF)

  1. Remove dangerous extensions
    Open Mozilla Firefox, click on the menu icon (top right corner) and select Add-ons Extensions. Click on menu icon and select 'Add-ons'
  2. Here, select Google and other questionable plugins. Click Remove to delete these entries. Select 'Extensions' and look for malicious entries. Click 'Remove' to get rid of each of them
  3. Change your homepage if it was altered by virus:
    Click on the menu (top right corner), choose Options General.
  4. Here, delete malicious URL and enter preferable website or click Restore to default.
  5. Click OK to save these changes. When in 'General' tab, delete malicious URL from 'Home Page' section or click on 'Restore to Default' button. Click 'OK' to save changes
  6. Reset Mozilla Firefox
    Click on the Firefox menu on the top left and click on the question mark. Here, choose Troubleshooting Information. Click on menu icon and then on '?'. Select 'Troubleshooting Information'
  7. Now you will see Reset Firefox to its default state message with Reset Firefox button. Click this button for several times and complete Google removal. Click on 'Reset Firefox' button for a couple of times

Get rid of Google from Google Chrome

To fix Google Chrome web browser and forget about redirects to unknown websites, you should double-check your extensions. Make sure you remove all entries that look questionable or that you can't even remember installing on your web browser:

  1. Delete malicious plugins
    Open Google Chrome, click on the menu icon (top right corner) and select Tools Extensions. Click on menu icon. Select 'Tools' and 'Extensions'
  2. Here, select Google and other malicious plugins and select trash icon to delete these entries. Look for malicious entries and delete each of them by clicking on the Trash bin icon
  3. Change your homepage and default search engine if it was altered by your virus
    Click on menu icon and choose Settings.
  4. Here, look for the Open a specific page or set of pages under On startup option and click on Set pages. After clicking on menu and 'Settings', select 'Set pages'
  5. Now you should see another window. Here, delete malicious search sites and enter the one that you want to use as your homepage. Click 'X' to remove malicious URLs
  6. Click on menu icon again and choose Settings Manage Search engines under the Search section. When in 'Settings', select 'Manage search engines...'
  7. When in Search Engines..., remove malicious search sites. You should leave only Google or your preferred domain name. Click 'X' to remove malicious URLs
  8. Reset Google Chrome
    Click on menu icon on the top right of your Google Chrome and select Settings.
  9. Scroll down to the end of the page and click on Reset browser settings. When in 'Settings', scroll down to 'Reset browser settings' button and click on it
  10. Click Reset to confirm this action and complete Google removal. Click on 'Reset' button to complete your removal

Remove Google from Safari

To remove Google virus from Safari, eliminate unwanted extensions and reset the browser.

  1. Remove dangerous extensions
    Open Safari web browser and click on Safari in menu at the top left of the screen. Once you do this, select Preferences. Click on 'Safari' and select 'Preferences'
  2. Here, select Extensions and look for Google or other suspicious entries. Click on the Uninstall button to get rid each of them. Go to 'Extensions' and uninstall malicious add-ons
  3. Change your homepage if it was altered by virus:
    Open your Safari web browser and click on Safari in menu section. Here, select Preferences as it was displayed previously and select General.
  4. Here, look at the Homepage field. If it was altered by Google, remove unwanted link and enter the one that you want to use for your searches. Remember to include the "http://" before typing in the address of the page. When in 'General', delete malicious URL and enter your desired domain name
  5. Reset Safari
    Open Safari browser and click on Safari in menu section at the top left of the screen. Here, select Reset Safari.... Click on 'Safari' and select 'Reset Safari...'
  6. Now you will see a detailed dialog window filled with reset options. All of those options are usually checked, but you can specify which of them you want to reset. Click the Reset button to complete Google removal process. Select all options and click on 'Reset' button

Do not let government spy on you

The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices. Avoid any unwanted government tracking or spying by going totally anonymous on the internet. 

You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using Private Internet Access VPN.

Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.

Backup files for the later use, in case of the malware attack

Computer users can suffer from data losses due to cyber infections or their own faulty doings. Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact – you can set this process to be performed automatically.

When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use Data Recovery Pro for the data restoration process.

About the author
Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions

Removal guides in other languages